Earlier quoted context omitted.
> The vast majority of password leaks we've seen over the past decade have been due not to malware but rather server compromises. Something to consider is that malware-based compromises of personal systems don't raise as much brouhaha as corporate-level compromises.
My statement is based not on frequency of news, but rather on my understanding of the provenance of passwords in password lists. The vast majority of passwords in password lists are sourced from service hacks; not from user malware. And that makes sense. Malware events net maybe thousands of user passwords? On a good day maybe 100k. But hacks of major services like LinkedIn ... those yielded hundreds of millions of p…
So, I suspect the reverse is true with standalone PC's being more likely to be compromised, what makes this less noticeable is it's harder to automated extracting value from those hacked accounts beyond sending gmail spam etc.
PS: This is also why cryptocoin software on users machines is basically a non starter.